Data Availability Services

Vendor:

First CVE: Jul 26, 2019 · Active for 6 years

61
Total CVEs
More Total CVEs than 98% of tracked products
30.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
3.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Data Availability Services over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2019
6 years ago
Most Recent CVE
Feb 25, 2020
2,341 days ago

CVE Severity & Scoring

Data Availability Services61 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local29 (47.5%)
Network15 (24.6%)
Unknown0 (0.0%)
Physical16 (26.2%)
Adjacent Network1 (1.6%)
Attack Complexity
Low55 (90.2%)
High6 (9.8%)
Unknown0 (0.0%)
User Interaction
None56 (91.8%)
Unknown0 (0.0%)
Required5 (8.2%)
Privileges Required
Low23 (37.7%)
High2 (3.3%)
None36 (59.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi
Oct 11, 20197.896YESYES
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (R
Jan 17, 20207.573NONO
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when usersp
Nov 7, 20199.831NONO
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It op
Sep 19, 20198.828NONO
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location
Dec 23, 20196.527NONO
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volu
Dec 17, 20197.826NONO
In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c,
Dec 8, 20197.826NONO
A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by
Nov 18, 20197.526NONO
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota
Aug 25, 20197.526NONO

Exploit Exposure

Signals from CVEs in this product scope (61 CVEs).

CISA KEV
2 CVEs
3.3% of CVEs· 97th percentile
Metasploit
2 CVEs
3.3% of CVEs· 96th percentile
Nuclei
1 CVE
1.6% of CVEs· 96th percentile
ExploitDB
2 CVEs
3.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (61 CVEs).

Media Mentions

Signals from CVEs in this product scope (61 CVEs).

Top CNAs Publishing CVEs For Data Availability Services

Top CWEs

Versions

No cataloged versions.